Multiple cross-site scripting (XSS) vulnerabilities in eyeOS before 0.9.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) eyeNav and (2) system/baixar.php.
https://exchange.xforce.ibmcloud.com/vulnerabilities/29190
http://www.vupen.com/english/advisories/2006/3780
http://www.securityfocus.com/bid/20213
http://sourceforge.net/project/shownotes.php?group_id=145027&release_id=450490